
The United Nations Development Programme says it experienced a data security incident that involved threat actors infiltrating its internal network and stealing confidential human resources data.
In a press release, the UN agency said that on March 27, it received a threat intelligence notification that threat actors infiltrated the local IT infrastructure in the UN City of Copenhagen and stole human resources and other confidential information.
“Actions were immediately taken to identify a potential source and contain the affected server as well as to determine the specifics of the exposed data and who was impacted,” UNDP said.
“UNDP is currently conducting a thorough assessment of the nature and scope of the cyber-attack, and we have maintained ongoing communication with those affected by the breach so they can take steps to protect their personal information from misuse. Additionally, we are continuing efforts to contact other stakeholders, including informing our partners across the UN system.
“UNDP takes this incident extremely seriously and we reiterate our dedication to data security. We are committed to continue working to detect and minimize the risk of cyber-attacks,” the agency added.
On March 27, a relatively new threat group using the pseudonym 8base ransomware claimed responsibility for the data security incident at UNDP and listed the organisation as a victim on its data leak site.
8BASE #ransomware group has added 4 new victims to their #darkweb portal.
— FalconFeeds.io (@FalconFeedsio) March 27, 2024
- HC Queretaro 🇲🇽
- UNDP 🇺🇸
- Isophon glas 🇩🇪
- Lindos Group Of Companies 🇬🇧#Mexico #USA #Germany #UK#8base #darkweb #databreach #cyberattack pic.twitter.com/rAS49zqnCb
The ransomware group claimed to be in possession of sensitive confidential information including personal data, accounting data, certificates, employment contracts, confidentiality agreements, invoices, receipts, and more.
The group gave UNDP a deadline of 6 days to pay a ransom to prevent the stolen data from being leaked or sold to the highest bidder. It is unknown whether the agency is in contact with the hacker group.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543